Jobiba hiring network

Staff Application Security Engineer Jobs

15 active opportunities · Updated for September 2026

Fresh results

15 shown

Explore current staff application security engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.

D
Datadog
📍 BostonRemote
1mo ago

As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach application security at scale. You'll define the frameworks, methodologies, and architectural patterns that engineering teams across Datadog adopt and apply independently. You're the person others come to when they don't know how to make something secure, and you reliably have an answer. You'll be a point of contact for our most complex security programs, often spanning multiple teams and multiple quarters. The role requires both depth (going very deep on specific problems when needed) and breadth (recognizing patterns across systems and drawing connections that others miss). Partnering closely with teams inside and outside the security org is key to success. You'll help shape the AppSec roadmap and make the case for where investment should go. We use our own platform. Logs, Dashboards, Service Catalog, and APM aren't just things we sell: they're tools the AppSec team uses to build security services, measure adoption of secure defaults, and communicate risk across the organization. AI is also part of the picture. Engineering at Datadog increasingly uses agentic tooling throughout the development lifecycle, and many of the products we ship to customers now include AI-powered features. Both create new attack surfaces, and defining our strategy for addressing them is part of this role. If using Datadog to observe Datadog's own security posture, building impactful tooling, and shaping how we secure AI-powered systems sounds like the right kind of problem, this role is worth a close look. What You’ll Do: Define and drive security standards and secure-by-default solutions, serving as the Application Security subject matter expert. Build security tooling and automation that scales security practices across engineering teams, and implement robust security observability to support our threat detection team with meaningful, actionable security signals. Lead threat mod

REMOTEpythonaisupply chain
View job →
O
Okta
📍 WashingtonFull-timeFrom $180K/yr
1mo ago

Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. The Security Team Okta is The World's Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transform how people move through the digital world, putting Identity at the heart of business security and growth. At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every box—we're looking for lifelong learners and people who can improve us with their unique experiences. Join our team! We're building a world where Identity belongs to you. The Staff Product Security Engineer Opportunity The Security team's mission is to strengthen Okta's position as the leading Identity-as-a-service solutions provider by identifying and resolving risks to employees, products, and, most importantly, our customers. The Staff AI Product Security Engineer joins a team with a clear mission: to shape the future of application security by researching and building systems that prove how AI can fundamentally augment, automate, and scale defense. This is a hybrid research, offensive and software engineering role centered on leveraging AI to uncover vulnerabilities, automate root cause analysis, automate exploitation, and generate secure code patches at cloud scale. This role is built for engineers who want to push the limits of what AI can do for security, from benchmarking SOT

typescriptpythonjava
View job →
F
Forma.ai
📍 TorontoFull-time
3 days ago

About Forma.ai: Forma.ai is a Series B startup that's revolutionizing how sales compensation is designed, managed and optimized. We handle billions in annual managed commissions for market leaders like Edmentum, Stryker, and Autodesk. Our growth has been fuelled by our passion for fundamentally changing and shaping how companies use sales intelligence to drive business strategy. We’re welcoming equally driven individuals who are excited about creating something big! The Opportunity As a Staff Security Engineer, you will be a hands-on technical leader strengthening security across Forma's application, cloud infrastructure, development lifecycle, internal systems, and incident-response practices. Security today is shared across Engineering and DevOps. You'll work closely with both teams and have real room to shape how Forma approaches security as we grow. Depending on your interests and the needs of the business, the role could develop into a deeper individual-contributor position or help build a dedicated security team. You'll work directly with Engineering, DevOps, IT, Product, Legal, and Privacy to identify risks, design practical controls, automate security processes, and help teams ship secure and reliable software. What you'll do Cloud and infrastructure security Design and implement security controls across Forma's AWS environments, with a focus on IAM, least-privilege access, service identities, and account boundaries. Embed security requirements into Terraform and other Infrastructure as Code, and improve secrets, certificate, encryption-key, and credential management. Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services. Application, data, and AI security Run threat modelling and security architecture reviews for new products, services, APIs, data pipelines, and third-party integrations

pythonawskubernetes
View job →
S
1mo ago

Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and teams across Europe and the US. As AI continues to shape the way we live and work, Synthesia develops products to enhance visual communication and enterprise skill development, helping people work better and stay at the center of successful organizations. Following our recent Series E funding round, where we raised $200 million, our valuation stands at $4 billion. Our total funding exceeds $530 million from premier investors including Accel, NVentures (Nvidia's VC arm), Kleiner Perkins, GV, and Evantic Capital, alongside the founders and operators of Stripe, Datadog, Miro, and Webflow. Location: Europe remote or London hybrid About the role: As our engineering and research organisation grows, so does the complexity of securing it. Our Application Security team is at the forefront of that challenge — building AI-native security tooling, embedding security into the development lifecycle at scale, and finding ways to make a small, highly capable team punch well above its weight. We're looking for an Engineering Manager to lead and grow the AppSec team. This is not a coordination role. You'll be leading a team of exceptionally senior and staff-level engineers who are deeply self-directed and technically excellent. To earn their trust and enable their best work, you'll need to be genuinely close to the craft — able to engage at depth on threat modelling, agentic security tooling, SDLC design, and application risk. You'll also own AppSec strategy and be accountable for how the function scales alongside a product organisation that is growing fast and leaning heavily into AI-assisted development. Important note: Anyone working as a manager within the Infosec team will need to follow the Infosec Team Management Tenets . Key Responsibilities: Lead, support, enable and grow the AppSec team — owning hirin

javascriptpythonjava
View job →
CH
Cohere Health
📍 HyderabadFull-time₹2K – ₹2K/yr
4 days ago

Opportunity Overview: This is a unique opportunity to join a high-caliber software engineering team that is experiencing rapid growth. You’ll play a key role in building impactful healthcare technology on a modern technology stack, with a focus on our core data and AI platforms. Your work will focus on enhancing the platform's key features while also balancing scalability, reusability, and performance. As a Staff Engineer on the Application Engineering team, you’ll serve as a senior technical leader - responsible for designing and delivering high-quality, scalable software systems that power Cohere Health’s core platform. You’ll act as a multiplier, elevating the technical bar for the team, mentoring engineers, and partnering with product, data, design , clinical and payment teams to deliver solutions that meet compliance, quality, and performance standards. This role is ideal for engineers who thrive on solving complex problems in healthcare, have deep expertise in building distributed systems including data solutions, and want to influence architectural decisions for security and scale, drive cross-collaborations for alignment, establish technical standards for consistency and evolve both application and data engineering best practices at scale. What you’ll do: Technical Leadership & Architecture Define and drive the architecture of large-scale, distributed application systems across the Cohere platform. Ensure solutions are secure, performant, maintainable, and compliant with NCQA, CMS, and payer requirements. Champion platform engineering best practices in CI/CD, testing, release management, and observability. Hands-On Engineering Write clean, maintainable, and well-tested code, primarily in modern frameworks (e.g., Python, TypeScript/React, Java/Kotlin). Lead the development of core features and APIs that directly impact providers, payers, and patients. Partner with DevOps and Data teams to ensure seamless integration, scalability, and operati

typescriptpythonjava
View job →
O
1mo ago

Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. Okta is The World’s Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transform how people move through the digital world, putting Identity at the heart of business security and growth. At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every box - we’re looking for lifelong learners and people who can improve us with their unique experiences. Join our team! We’re building a world where Identity belongs to you. The Security team’s mission is to strengthen Okta’s position as the leading Identity-as-a-service solutions provider by identifying and resolving risks to employees, products, and, most importantly, our customers. With the ever-increasing pace of cloud application adoption, companies are struggling to find ways to accurately assess risk and act at the speed of their business. The Staff Product Security Engineer, PSIRT position is crucial in ensuring that Okta’s systems and services meet the highest security standards and align with our customers’ requirements. This position requires leadership, an innovative mindset, and expertise in security operations, responsible disclosure, vulnerability management, and program management. This position is available to candidates in Ireland and Spain. What You Will Do R

awsgitrest
View job →
DU
1 day ago

About the Team At DoorDash we’re building the industry’s most scalable and reliable delivery network to support our three-sided marketplace of consumers, merchants, and Dashers. Security Engineering is paramount to the success of our business, and DoorDash Security aspires to be one the world’s most admired Security Engineering team. We are committed to building the world's most trusted on-demand, logistics engine for delivery! We're expanding our team of great minds to help us secure and maintain a 24x7, no downtime, global infrastructure system that powers DoorDash’s multi-sided marketplace of consumers, merchants, and drivers. About the Role Our Proactive Security Engineering team is looking for a Staff Security Engineer, Proactive Security to execute on Dasher Security Product Engineering following a forward deployed engineering Pod model.You will be a part of our inclusive, collaborative forward deployed engineering team responsible for building “paved road” Security Product controls directly into our Dasher products to ensure a safe, secure and resilient delivery network. This is not a classic Product Security role performing reviews and operating platform products, this is a forward deployed model where we operate in Pods that focus on domain code bases to build and ship Dasher Security Products focusing on application hardening, anti-app reversing, and payment security in our global Dasher ecosystem.This is a US remote position reporting directly to the Manager of our Proactive Security Engineering team. You’re excited about this opportunity because you will… Lead the technical direction and roadmap for hardening of Dasher Security Products at DoorDash. Partner cross-functionally with Product Engineering, Legal, Security Engineering Platform, Data teams and XFN partners to build “paved road” proactive security controls that enable secure by design AI products into DoorDash eco-system. Examples of Dasher Security Products this team will focus on i

REMOTEjavaaiExcel
View job →

Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. The role: We’re seeking a Staff Security Detection Engineer to build and mature SoFi’s machine learning–driven detection and anomaly detection program. You will own the detection and model lifecycle end to end; feature engineering, model training, tuning, and validation, operating over large-scale security data lakes and streaming pipelines. You’ll partner closely with our Security Operations Center (SOC), Security Operations Engineering, and Fraud programs to turn high-volume telemetry into high-confidence, low-noise detections at scale. What you’ll do: Design, build, and maintain machine learning models for anomaly detection (unsupervised clustering, time-series and seasonality baselines, isolation forests, autoencoders, risk scoring) with measurable precision/recall targets. Operationalize models and detections from notebook to production, including enrichment, correlation, and response playbook hooks (detection-as-code, CI/CD, model versioning, and rollback). Engineer and tune features from identity, endpoint, network, cloud, SaaS, and application telemetry stored in the security data lake to improve model signal quality. Partner with the SOC to triage, tune, and close detection feedback loops; use analyst dispositions as labels to retrain and improve models, reduce noise, and document runbo

pythonsqlaws
View job →
C
Cloudflare
📍 Distributed; HybridFull-timeHybrid$185K – $275K/yr
1mo ago

About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in. Available Locations Atlanta, US Austin, US Denver, US New York, US Toronto, Canada Washington DC, US Seattle, WA Remote candidates within North America will also be considered. About the Role The Security Platform team is an infrastructure/developer tools group tasked with building and operating powerful, resilient, and secure infrastructure and systems that enable other engineering teams to deliver products to our customers efficiently and secure

pythonawslinux
View job →
S
1mo ago

Note: if you are an intern, new grad, or staff applicant, please do not apply using this link and visit our jobs page for those specific postings. Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. About the Organization Secure Frameworks: We provide security guarantees for common threats, helping teams secure their services by default. We build and maintain core application-layer security libraries and frameworks for development teams, including web security frameworks, cryptography libraries, and other threat mitigations across the Stripe technology stack. More recently, our scope has expanded to protective measures for AI agents. We are a hands-on engineering team that builds security protections and frameworks, rather than conducting security reviews. Core Infrastructure : We’re the home for Stripe's critical tier0 infrastructure systems (Compute, Networking, DocumentDB, Distributed Caching and High assurance engineering). We build the foundational platform for Stripe products and services to allow them to operate at scale. We drive reliability, availability, efficiency and scalability of these systems. Developer Infrastructure : We’re responsible for the productivity of all developers at Stripe. Ensure Stripe’s engineers have a reliable, fast, and easy-to-use inner dev loop to maximize productivity while building everything from low-latency microservices to large-scale data pipelines and machine learning models. Reliability Insights and Excellence : We build tools and frameworks

restmicroservicesmachine learning
View job →
G
Godaddy
📍 United StatesFull-timeFrom $182K/yr
1mo ago

Location Details: At GoDaddy the future of work looks different for each team. Some teams work in the office full-time, others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely. This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings. This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands. GoDaddy is not currently considering candidates for this role in California, Seattle, or NYC. Join Our Team GoDaddy is hiring a Staff Software Engineer to help define and scale our Internal Developer Platform —a centralized system that powers how engineers across the company build, deploy, and operate software. This platform is used by 1,000+ engineers to manage everything from cloud infrastructure and application lifecycle to security, compliance, and cost transparency. In this role, you’ll operate as a technical leader at platform scale, shaping the architecture and direction of systems that directly impact engineering velocity across the company. You’ll work on high-impact initiatives such as AI-powered developer tooling, next-generation API platforms, and the evolution of a unified developer experience spanning APIs, CLI, and UI. This is a high-ownership, high-visibility role where Staff Engineers drive decisions, influence product direction, and partner across infrastructure, security, and platform teams. If you’re motivated by building systems that improve how other engineers work—and want to have a measurable impact on developer productivity at scale—this team sits at the center of GoDaddy’s engineering ecosystem. What You’ll Get to Do... Design and build platform services that power GoDaddy’s internal developer ecosystem, used by 1,000+ engineers. Lead architecture and technical direction for high-scale APIs, infrastructure orchestration,

typescriptreactnode.js
View job →
M
Mongodb
📍 CaliforniaFull-timeFrom $211K/yr
1mo ago

The Application Modernization Platform (AMP) team is tackling one of the industry's most critical challenges: leveraging Generative AI to transform rigid, legacy applications into modern, microservices-based architectures powered by MongoDB. We are building a comprehensive, SaaS-like platform, encompassing both the "brain" (multi-agent reasoning and orchestration) and the "hands" (the deployment platform and modernization toolset). This solution requires a robust platform foundation and infrastructure designed for a "build once, run anywhere" model, ensuring seamless operation regardless of a client's security or network constraints. A key challenge is balancing the need to tune our tools for each customer's unique tech stack and restrictive environments with making them easily extensible and scalable for common application modernization challenges. We seek an engineering leader for this high-visibility initiative. This role requires defining the high-level strategy and technical direction across all AMP engineering pillars, leading the execution of solving uniquely complex application modernization puzzles, and delivering an enterprise-grade product. The leader will minimize deployment friction, meet customer compliance requirements, and help shape the future of how global enterprises leverage GenAI. The ideal candidate is a hands-on technical leader who excels at leveraging GenAI capabilities, architecting complex distributed systems, and designing the orchestration agents necessary to reliably and fluidly run the entire software development lifecycle. This role will be based in North America's West Coast (PST), and offers a hybrid working model. The ideal candidate for this role will have 10+ years of software development and operations experience, with a focus on building platforms and distributable software infrastructure Deep experience in building data warehouses and core components for data processing systems Have experience in using GenAI in building comple

mongodbawsazure
View job →
M
Mongodb
📍 British ColumbiaFull-timeFrom C$209K/yr
1mo ago

The Application Modernization Platform (AMP) team is tackling one of the industry's most critical challenges: leveraging Generative AI to transform rigid, legacy applications into modern, microservices-based architectures powered by MongoDB. We are building a comprehensive, SaaS-like platform, encompassing both the "brain" (multi-agent reasoning and orchestration) and the "hands" (the deployment platform and modernization toolset). This solution requires a robust platform foundation and infrastructure designed for a "build once, run anywhere" model, ensuring seamless operation regardless of a client's security or network constraints. A key challenge is balancing the need to tune our tools for each customer's unique tech stack and restrictive environments with making them easily extensible and scalable for common application modernization challenges. We seek an engineering leader for this high-visibility initiative. This role requires defining the high-level strategy and technical direction across all AMP engineering pillars, leading the execution of solving uniquely complex application modernization puzzles, and delivering an enterprise-grade product. The leader will minimize deployment friction, meet customer compliance requirements, and help shape the future of how global enterprises leverage GenAI. The ideal candidate is a hands-on technical leader who excels at leveraging GenAI capabilities, architecting complex distributed systems, and designing the orchestration agents necessary to reliably and fluidly run the entire software development lifecycle. This role will be based in North America's West Coast (PST), and offers a hybrid working model. The ideal candidate for this role will have 10+ years of software development and operations experience, with a focus on building platforms and distributable software infrastructure Deep experience in building data warehouses and core components for data processing systems Have experience in using GenAI in building comple

mongodbawsazure
View job →
R
Replit
📍 Foster CityFull-timeRemote
10 days ago

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Team Product Platform builds and owns the shared foundations the rest of Replit is built on, spanning the full stack so every other team can ship features safely and quickly. Identity & Authorization defines how people, agents, sandboxes, and services prove who they are and what they can do. These systems protect critical product and service interactions across Replit's web product, Agent, enterprise controls, and internal services. Our work is high-leverage and horizontal: when identity and policy are clear, reliable, and easy to adopt, every other team can move faster without rebuilding security controls. We are a small, collaborative team that values curiosity and clear thinking over pedigree, and we work in the open by bringing each other the problem rather than just the request. We care more about how you reason and build than the route you took to get here. About the Role As a Software Engineer , you will design, build, and operate the identity and authorization systems that protect critical interactions on Replit, including Agent acting on behalf of a user or holding their own identity. The work is guided by a few simple questions: Can every protected request prove which workload made it, which principal it represents, and who is acting on that principal's behalf? Can product teams express policy once and trust the same decision across web, mobile, Agent, and internal services? Can enterprise administrators control who can access each workspace, app, connector, and Agent capability without navigating a permission maze as well as having a legible ledger of decisions? Can Agent act for a user across long-running and durable work without receiving broad or long-lived credentials? Are identity and auth

REMOTEtypescriptkubernetesrest
View job →
R
1mo ago

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role Join our Enterprise Platform team and build the infrastructure foundations that enable the world's largest organizations to run Replit within their security and compliance boundaries. As a Software Engineer on this team, you'll design and implement the deployment flexibility, networking capabilities, authorization systems, and data controls that enterprises require, from single-tenant architectures and private connectivity to custom policy enforcement and customer-managed encryption. You'll work at the intersection of cloud infrastructure and enterprise requirements, partnering with Platform Engineering, Security, and Sales to ship capabilities that unlock adoption at demanding organizations. What You'll Do Build enterprise deployment infrastructure: Design and implement single-tenant and dedicated deployment options, enabling customers to run Replit with the isolation guarantees their security posture requires. Implement private networking capabilities: Build VPC peering, private connectivity, and static IP configurations that allow enterprises to integrate Replit into their existing network architectures. Design authorization services: Build the authorization infrastructure that enforces custom enterprise policies; enabling fine-grained access controls, custom permission models, and policy enforcement that integrates with customers' existing identity and governance systems. Ship data protection features: Implement bring-your-own-key (BYOK) encryption, customer-managed keys, and data residency controls that give enterprises ownership over their most sensitive data. Develop infrastructure automation: Write Terraform modules and automation that enable reliable, repeatable enterprise deployments across reg

typescriptpythongcp
View job →
🔔

Get new staff application security engineer jobs by email

Daily job updates · Unsubscribe anytime